PT-2026-92069 · Freerdp+1 · Freerdp+1

·

CVE-2026-91950

·

Published

2026-09-15

·

Updated

2026-09-24

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.31.0
Description An out-of-bounds read occurs in the rdpdr dump packet() function due to a 32-bit unsigned integer wraparound during buffer bounds validation. A malicious RDP server can send a crafted RDPDR packet with the computerNameLen variable set to 0xFFFFFFF0 to bypass security checks. This allows memory reads beyond the packet buffer, which can lead to client crashes or the disclosure of heap memory in logs.
Recommendations Update to version 3.31.0 or later.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91950
GHSA-C5GR-HMQP-PWJ4

Affected Products

Freerdp
Ubuntu